What the vulnerability does
01Description
Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.
Explanation of Vulnerability in Simple Terms
The iPanorama 360 WordPress Virtual Tour Builder plugin through version 1.8.1 does not properly check user permissions before allowing access to certain functions. An unauthenticated attacker can read limited non-sensitive information from the site without logging in. The vulnerability requires no user interaction and affects only data confidentiality, not integrity or availability.
What an attacker can do
Read limited non-sensitive information from the site without authentication.
Potential impact on your site
Unauthenticated visitors can access information that should be restricted to logged-in users.
Conditions required to exploit
Network access to the WordPress site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities